Information Security Analyst, Mid-Level – DevSecOps
Posted 16hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
DevSecOps analyst securing AWS environments and CI/CD pipelines for SGA’s corporate systems. Automating vulnerability remediation, secrets management, and Secure by Design practices.
Responsibilities:
- Support the development team in implementing DevSecOps and Secure by Design practices
- Design, implement, and enhance CI/CD pipelines, incorporating security controls into the development process
- Integrate security tools into pipelines, including SAST, DAST, SCA, and container vulnerability scanning
- Automate security controls and processes
- Identify and remediate vulnerabilities in applications, dependencies, packages, images, and components
- Support the remediation of vulnerabilities identified by security tools, scanners, and technical assessments
- Implement security improvements in AWS environments, including services, configurations, permissions, networks, and resources
- Assess security configurations and propose improvements for AWS resources
- Support the hardening of systems, servers, containers, and infrastructure components
- Support the secure management of secrets, credentials, keys, and certificates
- Implement controls to prevent the exposure of credentials and sensitive information in source code, pipelines, and development environments
- Collaborate with developers, DevOps, infrastructure, and security teams to embed security throughout the development lifecycle
- Support the creation and continuous improvement of security standards and best practices for development and cloud environments
- Document implemented configurations, procedures, standards, and improvements
Requirements:
- Professional experience in Information Security, DevSecOps, Cloud Security, or related fields
- Hands-on experience with AWS
- Knowledge of CI/CD and experience with at least one pipeline platform, such as GitHub Actions, GitLab CI/CD, Azure DevOps, Jenkins, or a similar tool
- Knowledge of Git and software development workflows
- Knowledge of security in Linux systems
- Knowledge of Docker and containers
- Knowledge of secrets, credentials, keys, and certificate management
- Basic to intermediate knowledge of IAM and cloud access control
- Familiarity with SAST, DAST, SCA, and container scanning concepts
- Ability to analyze security issues and implement the corresponding remediation measures
- Collaborative approach and ability to work closely with development teams



















